Analysis: Ransomware Dominates the Cybercrime Landscape episode artwork

EPISODE · Oct 16, 2020

Analysis: Ransomware Dominates the Cybercrime Landscape

from Info Risk Today Podcast · host InfoRiskToday.com

The latest edition of the ISMG Security Report analyzes a new report that labels ransomware as the No. 1 cybercrime threat. Also featured: A former FBI agent offers an update on "disruptionware" attacks; how Tesla's autopilot is tricked by phantom images.

Episode metadata supplied by the publisher feed · Published Oct 16, 2020

Embed this episode

NOW PLAYING

Analysis: Ransomware Dominates the Cybercrime Landscape

0:00 0:00
of MATCHES

TRANSCRIPT · AUTO-GENERATED

Analysis on today's top cybercrime threat, and Phantom Images fool Tesla's Autocilot. These stories and more in this week's ISNG security report. Hi, I'm Anna Delaney. First up, Matthew Schwartz, executive editor of ISNG's Data Breach today in Europe, outlines some hard truths about today's top cybercrime threat.

What is today's top cybercrime threat? The biggest problem that we face right now would be to run somewhere. That's the former CEO of the UK's National Cybersecurity Center, Keirin Martin. Now a professor at Oxford University, Martin helped create the NCSC five years ago.

It continues to serve as the public facing arm of Britain's GCHQ intelligence agency. In recent years, Martin says ransomware's impact has continued to surge. For those who don't know ransomware works by encrypting the data and demanding payments ports to the encryption. In terms of the holy trinity of cyber security, confidentiality, integrity and availability, ransomware is traditionally threatened availability.

You can't use the data and that's why you've been sentenced to pay a ransom. So the obvious solution to that is backups and having backups that work. Of course, there is the other risk as ransomware attackers are now doing that they threatened to release the data, which is a different problem and not a serious one. But to my very last hours at the NCSC, if the phone rang in the middle of the night and said there's something happening and you need to pay attention to it, I would have thought this is a ransomware attack that has disrupted a public service.

In the quest for illicit profits criminals have continued to double down on ransomware. Innovation is rife, Europol, the EU's law enforcement intelligence agency last week released its seventh annual Internet organized crime threat assessment, which ranks ransomware as public enemy number one. For the past year, many gangs have been threatening to leak or auction stolen data unless victims pay a ransom, which has been driving many victims, unfortunately, to pay. Other element is that it increases the potential risk of, for example, a fine under the general data protection regulation, which requires companies and public organizations, obviously, to safeguard our data.

That's Europol's head of policy and development, Nicole S. Vandermeulen. So in that sense, it adds additional layers of pressure and really threatening the victim and at the same time from the criminal's perspective, ensuring they get some form of payment. It can either be from the victim because out of fear or it can be from another criminal when they've auctioned off the data.

And it really puts the victim in almost an impossible situation. The criminal groups behind the scenes are also using more targeted tactics, says Chris Ewell, director of Threat Research Capability at Edinburgh Security Firm Secure Works. The highest impact threat that we're seeing is what we would call post intrusion ransomware. So in the good old days of 2018, ransomware was really quite the contained threat.

Someone would click on an email, they would open an emotional attachment, they would encrypt some files on their hard drive, maybe get to a file share if it was lucky, and they would have to pay a few thousand pounds to get access to their data again. The criminal groups behind things like that, cottend on about two years ago, that there was a lot more money to be made if you could target entire organizations at once. So really start following this, what we would class as APT style tactics that we used to attribute to nation states and things to get into environments, get complete control of the environment, and then take it to them. And we've seen that in the news a lot, and we're rapidly seeing much more post intrusion ransomware incidents across our customers.

With the end of 2020 drawing mirror, it prompts this question, where cybercrime is concerned, will 2021 again be the year of ransomware? For information security media group, I'm Matthew Schwartz. We're listening to the ISMG security report on ISMG radio, your number one source for information security news. Among the more malicious and potentially dangerous cyber incidents affecting healthcare, energy, and other sectors are involving disruption-ware attacks, including ransomware that aim to shut down businesses, says retired FBI agent Jason G.

Weiss, an attorney and forensics expert, Marion Kolbasock McGee, executive editor of ISMG's healthcare info security site questioned Jason recently on the ways in which disruption-ware attacks are expanding and evolving in various industries, and who's behind them. Here is his response. The two main sectors have really taken the brunt of ransomware attacks in particular, which I refer to as a subset of disruption-ware. Actually, ransomware is like a tool in the disruption-ware toolkit.

I think it's a better way to look at it. But what I've seen is a tremendous growth in the attack metrics against hospitals and government institutions in particular, and recently there's been a widespread disruption-ware attack in the energy industry. And I think that is probably one of the more dangerous threats because our energy security grids are pretty much insecure in comparison to some of our other types of businesses. We're having a lot of attacks on schools and stuff like that, but ultimately those attacks are limited in the sense that many of those organizations just don't have a lot of money to even pay a ransom.

So they're going out to the deeper pockets. Or in some cases, unfortunately, there are the malicious users that literally want to shut things down and have used ransomware and disruption-ware attacks to actually shut places down and destroy businesses. And it's almost maniacal in the sense that they're not even doing it for money. They're doing it on a spike or for some political reason.

So with that said, who's behind these attacks from now? I'll put my FBI hat on and I'll use the term we used to love in the FBI called Transnational Organized Crime Groups. These are groups of threat actors that could be based anywhere. I expect a lot of them are probably based overseas where you have a little less problem in terms of dealing with American law enforcement especially.

And these groups have actually become organized and create them in the sense that they've become businesses in a sense. There's a group called Maze, for example, that literally not only tries to encrypt your network, but they'll steal data from your network. They'll post it on the internet as a negotiating tool and they actually differentiate the way they do their work. With some people have access to the data, some people have access to the money, it's become almost a business.

I would refer to it more as almost like the electronic mafia, for lack of a better term. And finally, Tesla's Driver Assistance Service, conveniently named Autopilot, has been known for having some safety issues in the past. And guess what? Researchers have found a new flaw, not one of poor code per se, but rather around models distinguishing between real and fake objects.

Here's I.S.N.G.'s Jeremy Kirk, managing editor of security and technology with more on the story. Could McDonald's advertisement crash your car? Strangely these days, it's in the realm of possibility and that's not because you've been distracted by a digital billboard with a crispy bacon cheeseburger. Researchers with Ben Gurion University in Israel found that Autopilot systems by Tesla and Mobileye could be tricked into reacting after seeing split second images or projections.

The success of the experiment shows yet another type of edge case risk that the drivers relying on Autopilot systems could face. Hackers have compromised digital billboard systems before, often with the aim of imparting humor, but also showing the vulnerability of infrastructure-related connected devices. The researchers say the problem is not one of poor code or a security one per se. Rather, they say the models of some semi-autonomous driving systems haven't been trained to tell the difference between real and fake objects.

The researchers focused on two types of advanced driver assistance systems, or ADASs. They looked at Tesla's HW system, which is considered semi-autonomous, and Mobileye 360. That's an external camera-based system that uses computer vision algorithms. A demonstration video shows how the Tesla Model X running the company's HW3 Autopilot would react to the display of a brief image.

The Tesla is shown at night on a two-lane road with a digital billboard on the left side of the road. The billboard shows the McDonald's advert, which features crispy bacon landing on a slice of cheese atop a beef patty. Then, for 500 milliseconds, a stop sign flashes. On the other hand, the Tesla's low to a stop just after the billboard.

The experiment was conducted at a very low speed. In another test, the researchers used projectors to display phantom images to see how the ADAS systems would react. Tesla's system recognized a projection of a person wearing a tuxedo as a real person, and subsequently applied its brakes. It also registered a projection of a vehicle as a real vehicle.

Solving the problem for the Mobileye and Tesla systems requires ensuring that the vehicles can distinguish the authenticity of an object. To fix the problems, the researchers developed a system called Ghostbusters that reduces the chance the systems will be fooled between 80 and 100%. Ghostbusters uses five lightweight deep convolutional neural networks to examine a presented object's reflected light, context, surface, and depth. The fifth model wraps all the other's determinations into a final call.

So what does this mean for driver system systems? Well, they're definitely still maturing, and as this research shows, there are edge case scenarios that could pose risks to drivers. For Information Security Media Group, I'm Jeremy Kirk.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Info Risk Today Podcast episode published?

This episode was published on October 16, 2020.

Can I download this Info Risk Today Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!